Privacy at a glance
We use personal information to answer enquiries, design and deliver requested travel, operate secure accounts, meet legal duties and protect the service. We do not sell personal information or share it for cross-context behavioural advertising. Travel delivery may require carefully limited disclosure to hotels, carriers, guides and other suppliers in China.
Scope and responsible business
This Privacy Policy applies to the ChinaHue public website, enquiry process, private customer account, booking workflow, traveller portal and related support communications. It does not govern a third-party site or service that publishes its own privacy notice.
The legal operator of the ChinaHue website—not merely the brand—must be named with its physical postal address in the collection notice and contact block before it accepts a North American enquiry or account. Once a booking is offered, the same entity or a clearly identified different contracting entity is responsible for booking information, except where a named supplier independently decides how it will use information under its own notice.
Our designated Privacy Officer coordinates access, correction, deletion and complaint requests. The published contact block must show the officer’s title, legal operator, postal address, email and telephone. Required travel-registration details must also appear at the stage required by the customer’s location and in the Booking Package before payment.
Information we collect
| Category | Examples and source | Primary purpose | Retention approach |
|---|---|---|---|
| Contact and enquiry | Name, email, region, intended dates, group size, interests and message, provided by you. | Respond, assess feasibility and prepare a tailored proposal. | For the enquiry relationship and a limited follow-up period, then deletion or de-identification unless a booking or legal need continues. |
| Account and security | Account ID, email, name, password hash, status, session data, sign-in events, IP-derived security identifiers and audit records. | Authenticate, control access, prevent abuse and preserve security evidence. | While the account is active, then for security, dispute and legal periods. Short-lived sessions and rate-limit records expire earlier. |
| Booking and financial records | Quote, itinerary, travellers, dates, order status, prices, tax lines, payment status, invoices, cancellations and supplier references. | Form and perform the booking, account for funds, support customers and meet tax or recordkeeping duties. | For the booking lifecycle and applicable tax, accounting, chargeback, limitation and regulatory periods. |
| Traveller identity and documents | Legal name, nationality, birth date, passport or visa details and document images, provided by a traveller or authorized booking contact. | Issue named tickets, make reservations, support entry formalities and deliver requested travel. | Only as long as needed for the stated task. The portal displays a configured deletion date for uploaded records where available. Suppliers may have separate lawful retention. |
| Health, accessibility and dietary details | Mobility needs, allergies, dietary requirements or limited medical information voluntarily provided for the trip. | Assess and arrange requested accommodations and support health or safety. | Limited to personnel and suppliers who need it and retained no longer than reasonably necessary, subject to incident or legal records. |
| Communications | Email, enquiry text, support messages, live-chat content, requests, feedback and complaint records. | Communicate, document instructions, provide support and resolve issues. | According to the relationship and subject matter; sensitive booking instructions may be retained with the order. |
| Device and website activity | Browser, device, timestamps, requested pages, approximate network location, error and security logs, session cookie and local preferences. | Operate, secure, diagnose and remember requested functionality. | Session or short operational periods unless a security event requires longer evidence. |
| Optional media and reviews | Photographs, video, testimonial, name or attribution supplied under a separate release. | Publish only in the channels and for the period authorized. | Until the documented permission ends or is withdrawn prospectively, subject to reasonable removal and legal records. |
We do not intentionally collect Social Security or Social Insurance numbers. Do not place card details, passport images, medical details or other sensitive information in a general enquiry or live-chat message.
Where information comes from
We collect information directly from you, from another traveller or lead booker authorized to act for you, from our staff during trip design, and from suppliers involved in a requested booking. We also generate transaction, access and security records when the Services are used. A payment provider may return status, amount, card brand and limited card identifiers, but not the full card number or security code.
If someone makes a booking for you, ask that person for the Booking Package and this policy. You may contact us to correct your information or confirm the authority under which it was provided.
How and why we use information
We use personal information when reasonably necessary to:
- respond to a requested enquiry and design, price, confirm and deliver a journey;
- create and secure an invited account, authenticate users and show the correct private proposal or order;
- book accommodation, transport, tickets, guides, dining and requested accommodations;
- process and reconcile payments, issue records and administer changes, cancellations, refunds and complaints;
- communicate operational information, provide support and protect traveller safety;
- detect fraud, investigate misuse, secure systems, debug failures and maintain audit evidence;
- comply with tax, accounting, sanctions, law-enforcement, consumer-protection and travel-industry duties; and
- create aggregate or de-identified business insights that are not reasonably linked to an individual.
We do not require consent for an unrelated secondary purpose as a condition of service. Where Canadian law requires consent, we seek a form appropriate to the sensitivity and reasonable expectations involved. Sensitive traveller information and optional promotional uses receive a clear, specific choice.
When we disclose information
We disclose only what is reasonably needed for the stated purpose to these recipients:
- Travel suppliers. Hotels, transport providers, ticketing partners, guides, venues, restaurants and local operators receive the traveller and booking details required to confirm and deliver their service.
- Technology and business processors. Cloud hosting and storage, support chat, email delivery, security, professional advisers and, when enabled and identified at checkout, payment processing providers operate under service arrangements and instructions appropriate to their role.
- Your group. The lead traveller and authorized group members may receive itinerary, status and shared booking information. We avoid disclosing one traveller’s sensitive information to another unless necessary and authorized.
- Legal and safety recipients. Regulators, tax authorities, courts, law enforcement, emergency responders, insurers or advisers may receive information when reasonably necessary and lawful.
- Corporate transaction recipients. A genuine prospective purchaser or successor may review limited information under confidentiality and must continue to protect transferred information.
We do not sell personal information for money and do not disclose it for cross-context behavioural advertising or targeted advertising based on activity across unrelated businesses. If that practice changes, we will update this policy and provide any required opt-out before beginning it.
Current technology providers
When you allow optional analytics, PostHog provides activity analytics and, if enabled, masked public-page replay as described in the cookies section below.
The current service uses Google Cloud Platform for application hosting, Firestore records and Cloud Storage. Private traveller uploads are kept in a bucket that blocks public access. If configured, tawk.to provides live chat and stores chat information under its service. Administrative invitation email may be delivered through Resend. A payment processor will be named at checkout before live card payment is enabled.
Providers can change as the service develops. We assess access, purpose, security, location and deletion terms before using a provider for personal information, and will update this policy when a change materially affects individuals.
International and cross-border handling
ChinaHue designs travel in China for customers who may be in the United States or Canada. Current cross-border processing locations are the United States, for application hosting, database, private file storage, email and support technology, and China, for the selected hotels, carriers, guides, venues and local operators that deliver a requested trip. Information is also viewed by the traveller from their own location. Local law may allow courts, law enforcement or national-security authorities to access information in the processing jurisdiction.
We limit cross-border disclosure to what is needed, use contractual and security safeguards appropriate to the sensitivity, and remain accountable for information transferred to a processor as required by applicable Canadian law. A hotel, carrier or government authority acting for its own purposes may have separate legal duties and retention rules.
The Privacy Officer maintains a service-provider register with the provider, country, purpose and data category and will make the relevant portion available on request. We will update this policy before adding a routine processing country. We do not accept Quebec enquiries through the current English-only service; a Quebec launch requires the applicable privacy impact assessment and written transfer arrangement before communicating personal information outside Quebec.
Payment information
Live online card payment is not currently enabled. Before it is enabled, checkout will identify the payment provider and merchant, show the full price and link the provider’s privacy information. Card-entry fields must be hosted or tokenized by the payment provider. ChinaHue systems are not designed to receive or store a complete card number or card security code.
We may retain transaction ID, payment method type, limited card digits, amount, currency, status, timestamps, fraud signals, refund records and invoices as needed to administer and prove the transaction.
Cookies, local storage and embedded services
The website uses a first-party, HttpOnly session cookie to keep an authenticated account signed in and to protect private routes. It is necessary for the customer account, is not available to page scripts and expires after the configured session period. The customer interface also signs out after a period of inactivity.
A travel-tips checklist may store completion choices in the browser’s local storage. Those choices stay on that device and are not the customer database. We do not use advertising cookies.
When configured, optional PostHog analytics starts only after you select “Allow analytics.” It records page visits, clicks, scrolling, time on pages, browser performance, and steps such as enquiry submission, sign-in and checkout status. A random browser identifier connects visits; after sign-in, an internal account identifier connects the permitted activity. We do not send names, email addresses, passwords, enquiry text, traveller documents or payment credentials to PostHog. Private route identifiers and URL query strings are removed from analytics events.
If session replay is enabled, PostHog can replay masked activity on public pages. Account, checkout, enquiry and administrative pages are excluded from replay; form fields, images, embedded chat and other third-party frames are blocked, and text and element attributes are masked. Request bodies, request headers and console contents are not recorded. Private account workflows send only selected step and status events.
PostHog processes this optional activity in the region configured for our analytics project. The browser stores your analytics choice and, if allowed, analytics identifiers. You can decline without affecting enquiries or bookings, and change your choice at any time through “Analytics preferences” in the website footer. Declining stops future collection and clears the analytics identifiers on this browser; it does not delete previously received events. Contact the Privacy Officer to request access or deletion. We also keep optional analytics off when the browser sends Global Privacy Control or Do Not Track.
If live chat is configured, tawk.to may use cookies or similar technologies and receives chat content plus limited account identity after authenticated sign-in. Embedded video or social services may receive device and activity information when you interact with them. These providers may recognize a browser across visits or unrelated sites under their own notices. You may use email instead of chat, and you must not send sensitive traveller or payment documents through chat.
Browser controls can delete or block storage, although blocking the essential session cookie prevents account sign-in. Optional PostHog analytics remains off until you choose to allow it. We do not use the analytics data for cross-site advertising.
Sensitive information and traveller authority
Passport, visa, health, accessibility and minor information receives heightened protection. We collect it only for a defined trip task, restrict access by role and booking, and use the secure traveller portal for files and structured forms. Each task must explain why the information is needed, who needs it and the deletion date or objective deletion trigger. Covered health information is also governed by our Consumer Health Data Privacy Policy.
A lead traveller who submits information for another person must be authorized. For another adult’s sensitive information, we may require that traveller’s direct confirmation. A parent or legal guardian must authorize processing for a minor who cannot provide meaningful consent.
We do not use sensitive personal information to infer characteristics, advertise, build unrelated profiles or make solely automated eligibility decisions.
For Washington or Connecticut residents, a task that could collect consumer health data must remain disabled until the separate state notice, required consent, privacy assessment, processor terms, recipient disclosure and deletion workflow are active.
Operational messages and marketing choices
Enquiry replies, requested quotes, security alerts, booking records, payment notices and itinerary updates are operational messages. We send them to perform a request or contract and not because you subscribed to marketing.
Promotional email or text messages require a separate, optional choice where consent is required. A marketing request must identify the legal sender, brand, purpose, postal address and working contact method and must not be pre-checked or bundled with account or booking acceptance. Each message includes a no-cost unsubscribe method. For Canadian recipients, contact details remain valid for at least 60 days after sending and an unsubscribe is implemented within 10 business days.
When Canadian law permits reliance on an existing business relationship rather than express consent, we apply and document the applicable expiry—typically six months for an enquiry and two years after a qualifying purchase—and stop at expiry unless another lawful basis exists. We retain the wording, source, time and recipient evidence for consent and keep suppression records so an address is not re-added. A reply limited to a person’s request is operational; lead nurturing or promotional material is treated as marketing.
Retention and deletion
We do not apply one indefinite period to every record. The current operating schedule uses the periods below unless a shorter period is stated at collection or a documented legal hold or statutory duty requires longer:
- An enquiry that does not become an active proposal or booking is deleted or de-identified 12 months after the last substantive contact.
- Account and booking, invoice, acceptance and refund records are retained through the trip and for seven years after the last transaction, or the shorter/longer period the contracting entity’s applicable tax, travel or limitation law requires.
- Passport, visa and health uploads are targeted for deletion from the active traveller record no later than 30 days after the trip ends or the requested arrangement is abandoned. A task may state an earlier date. A narrowly separated incident or consent record may remain without the underlying document.
- Support and live-chat records not attached to a booking are deleted after 24 months; a booking instruction or complaint follows the booking-record period.
- Session cookies expire under the period stated when issued, and public-inquiry rate-limit records expire after two hours unless connected to a documented security investigation.
- Optional promotional media is removed from future controlled use when permission ends or is withdrawn, subject to completed print runs, third-party sharing by viewers and legal evidence.
When a record is no longer needed, we delete it or de-identify it using a method appropriate to the sensitivity. The Privacy Officer maintains the actual backup cycle, supplier exceptions and legal-hold register; backup copies are isolated from ordinary use and age out under that documented cycle.
Security safeguards
Safeguards include access-controlled server APIs, account and object authorization, password hashing, secure session cookies, rate limiting, private cloud storage for traveller files, validation of file type and content, encryption in transit and at rest provided by the hosting platform, audit records and restricted administrative permissions.
No system is completely secure. We assess suspected incidents, contain and document them, and notify affected individuals and regulators where law requires. If you suspect unauthorized account or information access, contact us promptly.
Your choices and privacy rights
Depending on your location and applicable law, you may ask to:
- confirm whether we hold personal information about you and access a copy;
- correct inaccurate or incomplete information;
- delete information or close an account, subject to lawful exceptions;
- receive portable information in an available, commonly used format where required;
- withdraw consent for future processing that relies on consent, subject to legal or contractual limits explained at the time;
- opt out of sale, sharing, targeted advertising or certain profiling if we ever engage in a covered practice;
- limit a covered use or disclosure of sensitive personal information; and
- appeal a denied request where applicable and complain to a privacy regulator.
Email the Privacy Officer with the subject “Privacy request” and describe your request and relationship with us. We will verify identity proportionately and respond within the time required by law. We may ask an authorized agent for proof of authority and may ask you to confirm directly. We do not discriminate against someone for exercising a privacy right.
We may deny or limit a request where law allows, for example to protect another person, preserve transaction or security evidence, comply with a legal duty or avoid disclosing credentials. We will explain an applicable denial and appeal route.
United States state privacy notice
This section supplements the rest of the policy for residents of U.S. states with an applicable comprehensive privacy law. The categories collected in the preceding 12 months may include identifiers and contact information; customer and commercial records; internet or network activity; approximate location inferred from network information; audio, visual and communications content; travel preferences and inferences supplied for trip design; and sensitive information such as account credentials, government-document data and health or accessibility details.
Sources, business purposes, retention criteria and recipient categories are described above. We disclose relevant categories to service providers and travel suppliers for business operations and booking delivery. We do not sell these categories and do not share them for cross-context behavioural advertising. We do not knowingly sell or share information of people under 16. We use sensitive information only for requested service, security, safety and other purposes permitted without a right to limit, unless we first provide the required notice and choice.
Where applicable, you may exercise rights to know, access, correct, delete and obtain a portable copy, and to opt out of covered sale, sharing, targeted advertising or profiling. Because we do not currently engage in those opt-out practices, no data is exchanged when an opt-out signal is received; we will honour a legally recognized browser signal before beginning a covered practice. Washington and Connecticut residents should also review the separate Consumer Health Data Privacy Policy. Request statistics and additional state disclosures will be published if and when the business meets the relevant statutory threshold.
Canadian privacy rights
For Canadian commercial activity, we apply the accountability, identified-purpose, consent, limiting-collection, limiting-use/disclosure/retention, accuracy, safeguards, openness, individual-access and challenge principles required by applicable federal or provincial private-sector privacy law.
You may request access and correction, ask how information has been used and disclosed, withdraw consent subject to explained limits, and challenge our compliance with the Privacy Officer. If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator. Quebec residents may contact the Commission d’accès à l’information du Québec.
For Quebec residents, we will publish the Privacy Officer’s title and contact information, use privacy-protective defaults, provide required transparency at collection, assess covered system and cross-border projects, and support rights such as access, rectification, withdrawal and portability where applicable. These steps do not replace the separate French-language consumer contract requirements described in the Booking Terms.
Children
The website and accounts are for adults. We do not knowingly invite a child under 13 to create an account or submit information directly. For a Quebec child under 14, direct collection, use or disclosure requires the parent or guardian’s consent unless a narrow statutory exception clearly applies for the child’s benefit. An adult may provide limited information about a child traveller when needed to design or deliver family travel, and we require parent or guardian authority whenever applicable law or the child’s capacity requires it.
If you believe a child submitted personal information directly without appropriate authorization, contact the Privacy Officer so we can investigate and delete it where required.
Policy changes
The version and effective date appear at the top. We may update this policy to reflect a material change in technology, suppliers, law or business practice. We will post the new version and give additional notice or obtain consent when required. A material new use will not be applied retroactively without a lawful basis.
Contact the Privacy Officer
Use the contact below for a request, question or complaint. Include enough information to locate your records, but do not email passport images, payment credentials or medical documents.